開始使用存取控制 permissions-overview

在此頁面上:​熟悉Journey Optimizer中的核心存取控制概念,包括角色、許可權、沙箱,以及物件和屬性型存取控制,因此您可以規劃如何授與使用者正確的存取權。

Journey Optimizer可讓您定義並管理指派給不同使用者的許可權。 許可權是授權或拒絕存取產品內功能的一組許可權和限制。

Journey Optimizer的存取控制是透過Adobe CX Enterprise中的​ 許可權 ​提供。 此功能利用角色和原則,將使用者與許可權和沙箱連結。

若要設定Journey Optimizer的存取控制,您必須擁有組織的系統或產品管理員許可權。 可授予或撤銷許可權的最低角色為產品管理員。 可以管理許可權的其他管理員角色是系統管理員(無限制)。 如需詳細資訊,請參閱有關管理角色的Adobe說明中心文章

Journey Optimizer中的使用者管理是以這些重要概念為基礎:

  • 角色:角色是指共用相同許可權和沙箱的使用者集合。 這些角色可讓您輕鬆管理組織內不同使用者群組的存取和許可權。 角色具有一組統一許可權(許可權),可讓使用者存取介面中的特定功能或物件。
    透過Journey Optimizer,您可以從預先存在的​ 角色 ​範圍中進行選擇,每個角色都有不同的許可權層級,以指派給您的使用者。 深入瞭解此頁面上可用的​內建角色

  • 許可權:許可權是統一許可權,可讓您定義指派給​ 角色 ​的授權。 每個許可權都集中在資源(例如歷程或優惠)下,代表Journey Optimizer中的不同功能或物件。 在權限層級一節中了解更多 。

  • 沙箱:虛擬沙箱會將執行個體分割成個別的獨立虛擬環境。 沙箱是透過許可權中的角色指派。 深入瞭解使用沙箱

  • 物件型存取控制:限制物件存取的標籤。 這個方法能保護敏感的數位資產,避免未經授權的使用者存取,並確保進一步保護個人資料。 深入瞭解物件式存取管理

  • 以屬性為基礎的存取控制:管理特定團隊或使用者群組資料存取的授權。 以屬性為基礎的存取控制可讓管理員根據屬性控制對特定物件和/或權能的存取。 屬性可以是新增至物件的中繼資料,例如新增至結構欄位或區段的標籤。 管理員定義存取原則,其中包含管理使用者存取許可權的屬性。 深入瞭解以屬性為基礎的存取管理

讓我們深入探討

現在您已瞭解​ Journey Optimizer ​中的存取控制概念,您可以更深入探討這些檔案區段,以開始設定許可權。

AI Knowledge Reference

This section contains structured knowledge intended to support interpretation, retrieval, and question answering related to this topic.

For complete understanding, this information should be combined with the documentation on this page. Neither source is intended to stand alone; the page describes the feature, while this section provides additional context that helps disambiguate terminology, intent, applicability, and constraints.

  • TL;DR: Access control in Journey Optimizer is built on roles, permissions, and sandboxes managed through Adobe CX Enterprise Permissions, with additional layers of object-based access control (OLAC) and attribute-based access control (ABAC) for fine-grained data protection.

Intents:

  • Understand the five core access control concepts: roles, permissions, sandboxes, object-based access control, and attribute-based access control
  • Know who can configure access control (system or product administrator)
  • Navigate to the right documentation section for each access control topic
  • Plan an access control strategy for the organization

Glossary:

  • Roles: Collections of users sharing the same permissions and sandboxes; pre-existing built-in roles are available, and custom roles can be created (product-specific)
  • Permissions: Unitary rights defining the authorizations assigned to Roles, grouped under resources such as Journey or Offers (product-specific)
  • Sandboxes: Virtual environments partitioning the Journey Optimizer instance into separate, isolated virtual workspaces; assigned through roles in Permissions (product-specific)
  • Object-based access control: Labels applied to specific Journey Optimizer objects (journeys, campaigns, offers) to restrict access to authorized users (product-specific)
  • Attribute-based access control: Policies controlling access to objects or capabilities based on attributes such as labels added to schema fields or segments (product-specific)

Guardrails:

  • Configuring access control requires system or product administrator privileges (prerequisite)
  • The minimum role that can grant or withdraw permissions is a product administrator (as stated on the page)

Terminology:

  • Canonical name: Attribute-based access control — Acronym: ABAC — variants: attribute-based access management
  • Canonical name: Object-based access control — Acronym: OLAC — variants: object-level access control, object-based access management
  • Do not confuse: “Object-based access control” (restricts access to specific AJO objects like journeys, campaigns, and offers using labels) ≠ “Attribute-based access control” (restricts access to data attributes like schema fields and segments based on label policies)
  • Do not confuse: “Roles” (a collection of users with shared permissions and sandboxes) ≠ “Permissions” (the unitary rights grouped under resources that are assigned to roles)

FAQ:

  • Q: Who can configure access control in Journey Optimizer? — Users with system administrator or product administrator privileges.
  • Q: What is the minimum administrator level required to grant or withdraw permissions? — Product administrator.
  • Q: Are sandboxes managed independently of roles? — No; sandboxes are assigned through roles in the Permissions product.
  • Q: Where is access control for Journey Optimizer managed? — Through Permissions in Adobe CX Enterprise, which links users with permissions and sandboxes via roles and policies.
recommendation-more-help
journey-optimizer-help